2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1633 | LOW | 2 | 0.1% | Feb 19, 2024 | During the secure boot, bl2 (the second stage of the bootloader) loops over images defined in the table “bl2_mem_params_... |
| CVE-2024-20925 | LOW | 3.1 | 0.6% | Feb 17, 2024 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). S... |
| CVE-2024-20923 | LOW | 3.1 | 0.6% | Feb 17, 2024 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). S... |
| CVE-2024-20911 | LOW | 2.6 | 0.3% | Feb 17, 2024 | Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected a... |
| CVE-2024-20905 | LOW | 2.7 | 0.5% | Feb 17, 2024 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure S... |
| CVE-2024-1591 | LOW | 3.3 | 0.2% | Feb 16, 2024 | Prior to version 24.1, a local authenticated attacker can view Sysvol when Privilege Management for Windows is configure... |
| CVE-2024-23591 | LOW | 2.3 | 0.2% | Feb 16, 2024 | ThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023 were left in Manufacturing Mode which... |
| CVE-2024-0037 | LOW | 3.3 | 0.1% | Feb 16, 2024 | In applyCustomDescription of SaveUi.java, there is a possible way to view images belonging to a different user due to a ... |
| CVE-2024-25941 | LOW | 3.3 | 0.2% | Feb 15, 2024 | The jail(2) system call has not limited a visiblity of allocated TTYs (the kern.ttys sysctl). This gives rise to an inf... |
| CVE-2024-23603 | LOW | 3.8 | 0.3% | Feb 14, 2024 | An SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. Note: Software v... |
| CVE-2024-1454 | LOW | 3.4 | 0.4% | Feb 12, 2024 | The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment pr... |
| CVE-2024-23760 | LOW | 2.7 | 0.4% | Feb 12, 2024 | Cleartext Storage of Sensitive Information in Gambio 4.9.2.0 allows attackers to obtain sensitive information via error-... |
| CVE-2024-1439 | LOW | 3.3 | 0.3% | Feb 12, 2024 | Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbit... |
| CVE-2024-1433 | LOW | 3.7 | 0.8% | Feb 11, 2024 | A vulnerability, which was classified as problematic, was found in KDE Plasma Workspace up to 5.93.0. This affects the f... |
| CVE-2024-23319 | LOW | 3.5 | 0.2% | Feb 9, 2024 | Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message tha... |
| CVE-2024-0628 | LOW | 3.8 | 0.4% | Feb 7, 2024 | The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu... |
| CVE-2024-1048 | LOW | 3.3 | 0.3% | Feb 6, 2024 | A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will cr... |
| CVE-2024-20811 | LOW | 3.3 | 0.1% | Feb 6, 2024 | Improper caller verification in GameOptimizer prior to SMR Feb-2024 Release 1 allows local attackers to configure GameOp... |
| CVE-2024-20810 | LOW | 3.3 | 0.2% | Feb 6, 2024 | Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to g... |
| CVE-2024-23824 | LOW | 2.7 | 0.6% | Feb 2, 2024 | mailcow is a dockerized email package, with multiple containers linked in one bridged network. The application is vulner... |
| CVE-2024-21671 | LOW | 3.7 | 0.4% | Jan 30, 2024 | The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Mul... |
| CVE-2024-23743 | LOW | 3.3 | 0.4% | Jan 28, 2024 | Notion through 3.1.0 on macOS might allow code execution because of RunAsNode and enableNodeClilnspectArguments. NOTE: t... |
| CVE-2024-21336 | LOW | 2.5 | 0.5% | Jan 26, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2024-21383 | LOW | 3.3 | 0.4% | Jan 26, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2024-23217 | LOW | 3.3 | 0.4% | Jan 23, 2024 | A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.3 and iPadOS 17.3... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now